This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and 360Synk Ltd ("Processor").
TODO: Replace this placeholder with final legal text before public launch.
- Personal Data: As defined in UK GDPR
- Processing: Any operation performed on Personal Data
- Sub-processor: Third party engaged by us to process data
This DPA applies to Personal Data processed by us on your behalf through the Service.
You must:
- Ensure lawful basis for data collection
- Provide clear privacy notices
- Respond to data subject requests
- Report relevant security incidents
We will:
- Process data only on your instructions
- Ensure personnel confidentiality
- Implement appropriate security measures
- Assist with data subject requests
- Delete data on termination
- Provide audit cooperation
We use approved sub-processors listed at: https://360synk.co.uk/subprocessors
You will be notified of sub-processor changes with 30 days to object.
We use Standard Contractual Clauses for transfers outside UK/EEA.
- 256-bit TLS encryption
- Data encrypted at rest
- Access controls and authentication
- Regular security audits
- Incident response procedures
We will notify you of data breaches without undue delay, and within 72 hours where feasible.
This DPA remains in effect while we process Personal Data on your behalf.
DPA enquiries: dpo@360synk.co.uk